
Trump Blasts Fox News Host Shannon Bream Over Ballroom Questions
The Fox anchor asked one simple question, and the president lost his Sunday.
Anna Lee ·
The faucet works, but who is actually controlling it now.

Turn on your kitchen faucet and you probably never think about the computers that make the water come out. Someone else did. Starting the last weekend of July 2026, hackers broke into the control systems at water plants across the country, changed the passwords, and slammed the door on the people who actually run them. By early August, utilities in at least 12 states had reported getting hit. In some towns, the water pressure dropped. In others, crews had to run the whole operation by hand like it was 1975.
This wasn't some kid poking around for fun. Federal officials have called it one of the most serious attacks on American water systems in years. Here's what happened, who's getting blamed, and why so many water plants were sitting ducks.
Water plants don't run on fancy laptops. They run on small industrial computers called programmable logic controllers, or PLCs. These little boxes do the grunt work: opening and closing valves, running pumps, and keeping an eye on water pressure. A lot of them are connected to the internet so operators can check on things from home or from a phone.
That internet connection is exactly what got exploited. The attackers went straight for certain models made by Rockwell Automation under the Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 series. Once they were inside, they didn't try to poison anything. They just changed the IP addresses and set new passwords, which kicked the real operators out of their own equipment. Imagine your smart thermostat cranking the heat and then locking you out of the app. Now imagine that thermostat controls the water for 80,000 people.
The lockout was the whole point. A federal advisory later flagged a critical flaw in Rockwell's Logix controllers that has no vendor patch available, which made the break-ins even easier to pull off.
Minnesota was ground zero. Over July 26 and 27, more than 30 community water systems in the state got hit in a single coordinated wave. That included the city of Plymouth, a Minneapolis suburb with a population close to 80,000. Some systems had to be shut down completely.
Then it moved. By August 1, Michigan confirmed that nine of its water systems had been targeted. The state said it first found out after getting a federal alert warning about attempts to mess with the operational technology behind water systems, and then local reports started rolling in. Georgia's Clayton County Water Authority reported a disruption to part of its systems and had to put out a precautionary boil water advisory for parts of north Clayton County. South Dakota reported a utility incident too.
The FBI first said seven states had reported attacks. Within days, the count had climbed to 12 states. A cybersecurity specialist who focuses on the water sector told CNN that the scale and coordination of the Minnesota attacks were unprecedented.
Officially, nobody in the government has named a culprit. Unofficially, a lot of fingers are pointing in the same direction. Security researchers were among the first to suspect an Iran-linked group called CyberAv3ngers, a crew tied to Iran's Revolutionary Guard that has been hammering American infrastructure for a while now.
The timing is hard to ignore. Four days before Minnesota reported its attacks, a federal advisory got updated to warn that Iran-linked hackers were trying to disrupt PLCs across critical infrastructure using the same playbook this group is known for. That group has a reputation for going after small water and city facilities, which experts describe as the lowest-hanging fruit in American infrastructure. They've been at it since 2023.
There's a certain irony to it, too. One former cyber official pointed out that Iranians are now specifically targeting the same kind of industrial controllers the U.S. once went after inside Iran's nuclear program. What goes around, apparently, comes around through your water main.
Whenever infrastructure breaks, the politicians show up. This was no different. President Donald Trump, talking to reporters at Camp David, put the blame squarely on Minnesota's leadership. "I think I blame it on Minnesota because they're grossly incompetent," he said, taking a shot at Gov. Tim Walz.
Walz fired back with his own take. He suggested Iran was behind the attacks and blamed federal budget cuts for leaving water plants exposed. "DOGE took an axe to CISA and left the US exposed to cyberattacks," Walz said, referring to the federal cybersecurity agency. He also said Minnesota's own experts spotted the problem quickly and worked with local towns to shut it down. Two guys, one attack, two completely different stories. Sound familiar?
Here's the part that should bug you. The United States has somewhere between 150,000 and 170,000 water systems. The vast majority are small, locally run operations with barely any IT staff, and plenty have none at all. That's the exact profile these hackers keep going after.
Compare that to the power grid. The electric grid has to follow mandatory federal cybersecurity standards. Break the rules and there are real penalties. Water systems? There's no equivalent federal mandate. None. A former cyber official runs a volunteer program that pairs security experts with water utilities, and even that effort has only reached 21 out of roughly 50,000 unprotected small utilities. The volunteers are willing. The scale is just brutal. Most of these plants have a handful of people whose main job is keeping water flowing, not fighting off hackers halfway across the world.
One cybersecurity CEO summed up the core problem: much of the technology running these utilities was never built with today's threats in mind. It was designed to move water, not to survive a targeted attack from a foreign government.
Not every break-in caused a mess. But across the campaign, the confirmed effects included pressure loss, flooding, communications outages, boil water notices, and long stretches where crews had to run everything manually. The FBI noted that when water pressure drops far enough, it can create conditions where untreated groundwater seeps into pipes, which is why some towns issued those boil water advisories as a precaution.
The good news, and it matters: as of the reporting dates, there was no confirmed contamination of any drinking water at any affected utility. Georgia's boil water advisory got lifted after testing came back clean. The utilities that bounced back the fastest were the ones that could flip over to manual operation and keep the water moving while they sorted out the computers.
This attack was different from the 2023 version by the same suspected crew. Back then, they were mostly defacing systems and messing with the code files inside the PLCs. This time, it was all about the lockout. Change the password, change the address, and watch the operators scramble.
Federal agencies put out urgent guidance, and it's blunt. Get those PLCs off the open internet. If a plant needs remote access, run it through a VPN or a gateway device instead of leaving the controller sitting out there for anyone to find. They also told utilities to double-check every outside connection, including cellular modems that vendors may have installed and forgotten about, the kind that don't always show up in a routine security scan.
The FBI said it and its partners are "fully engaged" and "well-equipped to protect against cyber threats of all varieties." That's the standard line. The reality is messier. One expert framed the whole thing as a shot across the bow, and he laid out three reasons it stings. Civilian water utilities support military bases. Many of the targeted Minnesota systems back up data centers. And attacks like this chip away at people's trust in the government to keep basic things running, at a moment when the country is already split down the middle.
So the next time your water tastes a little off or the pressure dips in the shower, it's probably nothing. But now you know there's a whole invisible system of little computers deciding whether that faucet works at all, and a lot of them are protected by not much more than a password somebody in a faraway country was able to change in an afternoon.
More in this section

The Fox anchor asked one simple question, and the president lost his Sunday.
Anna Lee ·

A cardiologist who kept Dick Cheney alive just put seven questions on the record.
Anna Lee ·

One quiet government account explains how the bill got this big.
Anna Lee ·
This week

Politics

Crime

World

Entertainment

Sports